Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Step 3 of 8: Run assessment
Compliance Journey
Preview only

Run assessment

Use available evidence and guided answers.

View Home

Preview mode

Live connectors, billing, AI, and downstream writes are off. Your assessment workspace may still be saved when hosted persistence is active.

Run your assessment

What this page does: The workbench helps answer assessment questions for the chosen framework/scope. ZAGOS uses answers and available evidence to identify gaps and prepare findings. Live connectors are parked until approved.

Your current setup

If no persisted scope exists, the page uses safe preview defaults.

You have answered 442 questions.

Your next safe step: Scroll down to answer questions or review scope.

Assessment progress
What is complete:

Answered questions show readiness direction for your selected frameworks.

What needs attention:

Unanswered questions become gaps or follow-up items. Live connector evidence remains parked until approved.

After this assessment:

Results remain preview/guided unless durable persistence is explicitly enabled and saved by a workspace owner.

Next best action:
Review framework scope
1
Answer questions
Needs review
2
Generate gaps/findings
Preview only
3
Link evidence
Parked
4
Assign remediation
Parked
5
Prepare report pack
Parked
Technical scope controls & legacy workbench

Answer coverage

442/442 answered (100%)

Readiness

60/100 readiness

Save location

This browser only

60Score
Audit scope
Frameworks, mode, search and filters for this audit run.
Question answer panel
Showing 40 of 692 questions. Edits update local state.

Biometrics & Remote Identity

6 / 6 done

How is valid consent or another lawful basis obtained for biometric processing?

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

What are the retention and deletion practices for biometric templates?

Manual
high
gdpr
ccpa
eu-ai-act
retention policy
data flow record
consent record
system inventory

Are there liveness detection or anti-spoofing controls (e.g. attacks using photos, masks, recordings)?

Manual
high
gdpr
eu-ai-act
consent record
system inventory

What is the primary purpose of the biometric processing?

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Is the system used for remote biometric identification in publicly accessible spaces?

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Which biometric modalities are used by the system?

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Biometrics – Accuracy & bias testing

10 / 10 done

Additional notes / context.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Describe the control/requirement and how it is implemented.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Evidence links / artifacts.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Is this tested and periodically reviewed?

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Known failure modes and mitigations.

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Residual risk

Manual
high
gdpr
eu-ai-act
iso-42001
consent record
system inventory
data flow record

Biometrics – Consent/notice & transparency

10 / 10 done

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Describe the control/requirement and how it is implemented.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Evidence links / artifacts.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Is this tested and periodically reviewed?

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Known failure modes and mitigations.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Residual risk

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory
workflow record

Biometrics – Lawful basis & necessity

9 / 10 done

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Describe the control/requirement and how it is implemented.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Evidence links / artifacts.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Is this tested and periodically reviewed?

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Known failure modes and mitigations.

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Residual risk

Manual
high
gdpr
eu-ai-act
consent record
policy document
system inventory

Biometrics – Security and anti-spoofing

10 / 10 done

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Additional notes / context.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Describe the control/requirement and how it is implemented.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Evidence links / artifacts.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Is this tested and periodically reviewed?

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Known failure modes and mitigations.

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Residual risk

Manual
high
gdpr
eu-ai-act
consent record
system inventory

Controls & Evidence

4 / 5 done

Biometrics & Remote Identity: Describe the current state for this area.

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Is there a named owner/accountable role for this area?

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Known risks/issues and mitigations?

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Maturity level

Manual
low
gdpr
eu-ai-act
consent record
system inventory

What evidence exists (policies, logs, reports, records)?

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Stakeholders & Impact

5 / 5 done

Biometrics & Remote Identity: Describe the current state for this area.

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Is there a named owner/accountable role for this area?

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Known risks/issues and mitigations?

Manual
low
gdpr
eu-ai-act
consent record
system inventory

Maturity level

Manual
low
gdpr
eu-ai-act
consent record
system inventory

What evidence exists (policies, logs, reports, records)?

Manual
low
gdpr
eu-ai-act
consent record
system inventory
Advanced actions: Open board pack preview View saved runs
Automated findings previewAs you answer, ZAGOS automatically derives draft findings, tasks and framework coverage from your answers. No live connectors or AI are used and nothing is sent anywhere — this is a preview. Saving your run turns it into a tracked work queue.
Save audit run
This assessment is in this browser workspace only and may not be visible to other team members. Check the workspace connection before relying on this for client delivery.

Readiness score

60/100

Findings

232

Evidence gaps

449

0 weak

Workflows

8

Outcome split
Pass 180
Partial 138
Fail 94
N/A 30
Framework readiness
gdpr62attention
iso-2700164attention
eu-ai-act58attention
iso-4200160attention
soc263attention
iso-2800063attention
zagos-cloud-api-guard0at-risk
Next best actions
Collect retention_policy, data_flow_record, consent_record, system_inventory (owner: Data Protection Office).
high
Collect consent_record, system_inventory (owner: Data Protection Office).
high
Collect consent_record, policy_document (owner: Data Protection Office).
high
Collect policy_document, system_inventory (owner: AI Governance Lead).
high
Collect policy_document, system_inventory (owner: AI Governance Lead).
high
Generated findings
232 total (showing 8).

What are the retention and deletion practices for biometric templates?

high

Collect retention_policy, data_flow_record, consent_record, system_inventory (owner: Data Protection Office).

Which biometric modalities are used by the system?

high

Collect consent_record, system_inventory (owner: Data Protection Office).

Is the service directly targeted at children or likely to be used by them?

high

Collect consent_record, policy_document (owner: Data Protection Office).

What are the main misuse / dual-use risks and how are they mitigated?

high

Collect policy_document, system_inventory (owner: AI Governance Lead).

Does the system implement logging that is sufficiently detailed to support traceability (Art. 12)?

medium

Collect audit_log (owner: CISO / Security).

Is there a documented risk management framework for this AI system (Art. 9)?

high

Collect policy_document, system_inventory (owner: AI Governance Lead).

Summarise the controls in place for accuracy, robustness and cybersecurity (Art. 15).

high

Collect policy_document, system_inventory (owner: AI Governance Lead).

How are adverse decisions explained to customers (reasons, factors, rights to contest)?

high

Collect workflow_record, policy_document (owner: AI Governance Lead).

Workflow recommendations

Ai risk assessment

33 questions need this.

high

Document human oversight

31 questions need this.

high

Renew supplier assurance

30 questions need this.

high

Classify ai system

26 questions need this.

high

Capture consent evidence

10 questions need this.

high

Access recertification

3 questions need this.

high

Publish retention schedule

1 questions need this.

high

Collect audit logs

4 questions need this.

medium
Automated risks & tasks
Loading engine...

No automated risks or tasks detected yet.

This assessment is in this browser workspace only and may not be visible to other team members. Check the workspace connection before relying on this for client delivery. No AI and no third-party connectors are used. ZAGOS Full Suite remains protected and separate.